tha-shed // daily build

The Verification Gap: when AI reviews its own code — and the language it writes fastest

OpenAI just let an AI model block its own engineers’ pull requests, no human required. Sonar’s 2026 survey says 96% of developers don’t trust AI code anyway. And a 13-language benchmark of AI coding agents just handed Ruby a win over Rust. Two data points, one week, one question: when the AI is doing the typing, what actually holds up?

Sep 11 2026 · 8 min interactive read · AI/DevOps + Ruby vs Python

01The AI gatekeeper is real now

On The Pragmatic Engineer podcast this week, OpenAI Codex lead Thibault Sottiaux confirmed every PR from an OpenAI engineer now passes a mandatory, automated AI security review — and the model can stop a merge outright, no human override required to enforce it. Meanwhile Sonar’s 2026 State of Code Developer Survey (1,100+ devs) found trust hasn’t caught up to adoption. Run the three scenarios below the way the gatekeeper would.

42%
of committed code is AI-generated today (65% projected by 2027)
96%
of developers don’t fully trust AI-written code
48%
say they always verify it before committing
24%
of the work week spent checking/fixing AI output